November 15, 2023· Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security
conference-paper
Open access
Batchman and Robin: Batched and Non-batched Branching for Interactive ZK
Abstract
Vector Oblivious Linear Evaluation (VOLE) supports fast and scalable interactive Zero-Knowledge (ZK) proofs. Despite recent improvements to VOLE-based ZK, compiling proof statements to a control-flow oblivious form (e.g., a circuit) continues to lead to expensive proofs. One useful setting where this inefficiency stands out is when the statement is a disjunction of clauses \mathcalL _1 łor \cdots łor \mathcalL _B. Typically, ZK requires paying the price to handle all B branches. Prior works have shown how to avoid this price in communication, but not in computation.
Community
0 commentsUse Connect Wallet in the navigation
No discussion yet
Be the first to share a question or observation.